global
Variables
Utilities
CUSTOM STYLES

Law 21,719: How to Prepare Your Company's Security Before December 2026

Nextfense
Team
August 5, 2026

On December 1, 2026, Law 21,719—the reform that modernizes Chile's personal data protection framework—will fully enter into force. It represents the most significant change in this area in more than two decades and marks a turning point: for the first time, Chile will have a Personal Data Protection Agency empowered to supervise compliance, conduct investigations, and impose sanctions.

Most articles about this law focus on its legal aspects: lawful bases for processing, contracts, consent, or contractual clauses. While all of these are important, one equally critical aspect often receives less attention.

Compliance with Law 21,719 is not just about having the right documentation—it also requires demonstrating that personal data is effectively protected.

That demonstration does not come from a contract. It comes from the evidence generated by your technology and processes: implemented security controls, audit logs, documented procedures, and a cybersecurity strategy capable of withstanding regulatory inspections or responding effectively to incidents.

In this article, we examine Law 21,719 from that perspective and review the technical measures organizations should begin implementing now to be ready before December 2026.

What Is Law 21,719, and Why Could It Apply Even If Your Company Is Not in Chile?

Published on December 13, 2024, Law 21,719 thoroughly modernizes the former Personal Data Protection Law (Law 19,628), updating Chile's regulatory framework for a digital environment where cloud computing, e-commerce, social media, and artificial intelligence are part of everyday business operations.

Its approach is inspired by the European Union's General Data Protection Regulation (GDPR), adopting similar principles and obligations while preserving the specific characteristics of Chile's legal system.

There are two key points organizations should understand from the outset.

The first is that the law applies to any public or private organization that processes personal data belonging to individuals located in Chile. The obligation applies equally to startups and large enterprises; what differs is the level of security measures expected, which must be proportionate to the risks associated with the processing activities.

The second point is that the law may have extraterritorial reach. Not every organization subject to the law will be established in Chile. In certain circumstances, the regulation also applies to foreign companies processing the personal data of individuals located in Chile, even if those companies operate from another country.

If your organization offers products or services to people in Chile or processes personal data in connection with those activities, it is important to assess whether Law 21,719 applies to your business.

The Biggest Challenge Is Not Legal—It's Proving That You Protect Personal Data

One of the pillars of the new regulation is the principle of accountability. It is no longer enough for an organization to claim compliance—it must be able to demonstrate it.

The law also incorporates the principle of security, requiring organizations to implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, destruction, or improper disclosure.

In practice, this means that regulatory inspections are no longer limited to reviewing contracts or internal policies. Authorities may also request evidence showing how the organization protects information, manages user access, responds to incidents, and implements security controls.

At this point, compliance ceases to be solely a legal matter and becomes a shared responsibility involving IT and cybersecurity teams.

Technical Measures You Should Start Implementing

Law 21,719 does not prescribe a fixed checklist of security controls. Instead, it requires organizations to adopt appropriate technical and organizational measures based on the nature of the data processed, the risks involved, and the characteristics of each organization.

In practice, a security program aligned with these principles typically includes measures such as:

  • Encrypting data both at rest and in transit.
  • Implementing least-privilege access controls, complemented by multi-factor authentication (MFA) and proper privileged identity management.
  • Maintaining audit logs that record who accessed, modified, or deleted information and when each action occurred.
  • Deploying Data Loss Prevention (DLP) solutions to reduce the risk of data exfiltration.
  • Securely managing both corporate and personal devices through endpoint management solutions and remote wipe capabilities where appropriate.

The specific controls implemented will depend on each organization's context. What matters is that the selected measures are proportionate to the risks involved and can be justified during a regulatory inspection.

The Record of Processing Activities (ROPA): The First Document Regulators Will Likely Request

The law requires organizations to maintain a Record of Processing Activities (ROPA), documenting what personal data is processed, for what purposes, the legal basis for processing, the parties involved, retention periods, and any transfers to third parties.

From a legal perspective, the ROPA is a cornerstone of compliance. However, preparing it correctly depends on something far more technical: knowing exactly where your personal data resides.

That is why one of the first steps is often a data discovery and classification exercise. This process identifies personal information stored across databases, cloud services, SaaS applications, email systems, and shared repositories.

Only with that level of visibility is it possible to build a reliable ROPA and determine which information requires protection and which controls are appropriate in each case.

Simply put, you cannot document—or protect—data you do not know exists.

Data Protection Impact Assessments (DPIAs): Assess Risks Before High-Impact Processing Begins

Law 21,719 introduces the obligation to conduct a Data Protection Impact Assessment (DPIA) whenever a processing activity may pose a high risk to individuals' rights and freedoms.

This may include large-scale processing, profiling with significant effects, systematic monitoring of public spaces, or the processing of special categories of personal data.

Organizations implementing AI solutions that process personal data should also evaluate whether the associated risks require a DPIA before deployment.

Incident Management: Prepare Before a Breach Happens

When a personal data breach occurs, Law 21,719 requires organizations to notify the Personal Data Protection Agency without undue delay. In addition, if the breach presents a high risk to individuals' rights, affected data subjects must also be informed.

One point often causes confusion. The widely known 72-hour notification deadline does not come from Law 21,719 but from Chile's Cybersecurity Framework Law (Law 21,663), which establishes that timeframe for reporting certain cybersecurity incidents to the National Cybersecurity Agency (ANCI).

In many organizations, both regulations will apply simultaneously. A single incident may trigger reporting obligations to two different authorities, each with distinct requirements.

For that reason, having a documented, tested, and well-understood incident response procedure is no longer simply a best practice—it is a key compliance requirement.

Fines: Why Data Protection Has Reached the Executive Agenda

The new sanctions regime is one of the law's most significant changes.

Penalties may reach up to 20,000 Monthly Tax Units (UTM) and, in certain circumstances established by law, up to 4% of an organization's annual revenue. Additionally, the Agency will have the authority to initiate investigations on its own initiative, order corrective measures, and maintain a National Register of Sanctions.

Beyond the financial impact, investigations and sanctions can damage the trust of customers, business partners, and investors.

As a result, data protection is no longer solely an IT issue—it has become a core business risk management concern.

How Can an Organization Demonstrate Compliance?

One of the key differences between Law 21,719 and the previous regulatory framework is that compliance must be demonstrable.

During an inspection, organizations will need more than statements claiming they protect personal data—they will need evidence.

Such evidence may include approved policies, data inventories, audit logs, implemented access controls, risk assessment documentation, incident response procedures, employee training records, and any other documentation demonstrating that appropriate measures have been adopted to address identified risks.

In other words, the objective is not only to have security controls in place, but also to prove that they exist, operate effectively, and are properly managed.

Roadmap to Be Ready Before December 2026

A compliance program typically requires several months of work. A practical implementation roadmap could include:

  • Conducting a gap assessment against the requirements of Law 21,719.
  • Identifying and classifying personal data throughout the organization.
  • Preparing the Record of Processing Activities (ROPA).
  • Implementing or strengthening technical security controls according to identified risks.
  • Performing Data Protection Impact Assessments (DPIAs) where required.
  • Defining and testing an incident and data breach response procedure.
  • Reviewing contracts with third-party data processors.
  • Training employees and reinforcing confidentiality obligations.

Although December 2026 may seem far away, compliance projects rarely can be completed in just a few weeks. Starting early allows organizations to prioritize risks, allocate resources effectively, and ensure they are fully prepared when the law takes effect.

Frequently Asked Questions About Law 21,719

When does Law 21,719 enter into force?

Its full implementation begins on December 1, 2026, following the implementation period established by the law.

Can it apply if my company is not located in Chile?

Yes. The law has extraterritorial scope and may apply to organizations processing the personal data of individuals located in Chile, even if those organizations operate from another country.

Is appointing a Data Protection Officer (DPO) mandatory?

The law does not establish a general obligation for every organization. However, it recognizes this role, and appointing a DPO may be required or advisable depending on the organization's circumstances and compliance model.

Does the law require reporting a data breach within 72 hours?

No. Law 21,719 requires notification without undue delay. The 72-hour deadline belongs to Chile's Cybersecurity Framework Law for certain reports submitted to the National Cybersecurity Agency (ANCI).

What is the maximum fine?

Penalties may reach up to 20,000 UTM and, in certain circumstances established by law, up to 4% of an organization's annual revenue.

Prepare Your Organization with Nextfense

Adapting to Law 21,719 is an ongoing process—not a project that ends once a policy has been drafted or a contract has been signed. It requires maintaining a cybersecurity posture capable of preventing risks, detecting incidents, and demonstrating that security controls are working effectively.

At Nextfense, we help organizations navigate this journey by combining specialized cybersecurity consulting with Core, our cybersecurity management platform, which centralizes visibility across the IT environment, enables continuous monitoring, and provides the evidence needed to strengthen compliance and improve incident response.

The sooner your organization begins its compliance journey, the more time it will have to implement improvements strategically and reach December 2026 with a robust and effective data protection program.